Free Essay

Jit2 Task 1

In:

Submitted By williamlonghair
Words 3198
Pages 13
BILLS DRUGS RISK REGISTER

Risk Description Source Likelihood of Occurrence* Severity of Impact* Controllability*
Inability to receive merchandise from suppliers in china.
* Global risk A large portion of our generic pharmaceuticals and merchandise are manufactured in china. Any Trade embargos or military involvement would make those resources unavailable and cause a severe merchandise shortage. This will impact sales and profits. China has been aggressive posturing and advancing its military interests. if this trend continues this could lead to trade embargos and/or military involvement. Medium - China has slowly building up to the current level of posturing. At this time it is unknown how far they will go. High - The companies main source of income is the sale of goods. If Bills Drugs is unable to resupply, financial loss will follow. low - We cannot effect the outcome of this potential event. We can only attempt to mitigate it's effects.
HIPAA Data exfiltration by attack of the company network. The company network has been compromised and Health Insurance Portability and Accountability Act data has been exposed. A hacker successfully attacked the company network. Using A combination of social engineering, and the exploitation of un-patched servers was able to penetrate the corporate network. Medium - Our information security measures have discouraged or stopped many attacks. Given the sheer volume of potential attackers and attacks, no network is 100% secure. High -There will be fines and we will need to prove that we have been diligent in the protection of this data. Also there will be the damage to our public image that will need to be addressed. Medium - Through proper application of security controls and continuous monitoring we can lessen the likely hood of this event.
A pharmacy gives a customer incorrect prescription medicines. a pharmacy has dispensed the incorrect medicine to a customer. Through some form of human error such as inattention to detail or possibly distraction is the cause of this. A pharmacy team provided incorrect pharmaceuticals to a customer. Medium. - given the sheer volume of prescriptions filled and long hours worked. this happens from time to time. Medium - depending on many factors, this could be as simple as a customer returning the incorrect product. Also errors like this could lead to customer fatalities . There may be fines involved depending on the pharmaceuticals involved . There will be some form of damage to our public image because of incompetence. Litigation against the corporation as well as the individual pharmacist are also a possibility. High -
By the insertion of more checks into the currently existing procedures this risk can be controlled. The enforcement of standards and procedures can further control the likelihood of this risk occurring.
A robbery at a Bill's Drug location. A Bills Drugs has been robbed. all cash in the store has been taken. Both violent and non-violet robber y on the rise. Any business that has cash on hand is a potential target. Medium - if a location has cash on hand there is the potential for robbery. while specific locations are more likely than others the aggregate is a medium severity. Medium – as long as no destruction of property or loss of life is incurred. While there is a financial loss, a public image issue is also incurred. The image that we are easy targets is potentially there, this could lead to greater frequency of robbery. Medium – With good security and systems in place a location becomes less attractive as a target. A less attractive target can mean the difference between being a victim and being bypassed by a criminal.
Economic recession Due Economic recession the customer base is spending less A significant decline in economic activity lasting for an extended period. Many sources define the period as being at least several months in length. High -
Economic recessions happen periodically, and they will continue do so. Given that, there is a high probability that this risk will be realized. High - losses in profits will be realized.
There will be less revenue generated from all streams and the cost of products will go up. low - we cannot control the factors that cause this event. All that can be done is to attempt to mitigate the effects on the company.
Power outage at store with expected duration of less than one hour. Power outage on the local grid. After contact with local power provider the duration is to be one hour or less. Power outage on the local grid with a variety of potential causes, transformer failure, lightning, or wind to name a few possible causes. low - while this event is unpredictable, on average these events happen at least twice a year at our stores. it should be noted that this number is an average. The individual number could be substantially higher or lower based on the areas infrastructure. low - if there is no power at the store, shoppers cannot be allowed in for liability reason. customers already inside will not be allowed to complete their purchases, Without power the point of sales systems will not work, and only emergency lighting will be available.

med - with a backup power supply this can be a completely controlled customers in the store can complete their purchases and leave the store safely.
Loss of customer prescription data due to localized IT failure Loss of customer prescription data due to Hard drive/ computer failure at the store level. Failure of computer hardware/ software High – all hardware fails over time. Medium -
All store pharmacy at the effected site will be inaccessible. Prescriptions cannot be filled, also there will be damage to customer satisfaction and public image. High – data can be backed-up locally and off site.
Work related back injury (store level) A staff member injures back during the unloading of a delivery and or restocking functions. Staff member suffered back injury stemming from improper lifting technique and not using hand truck to move heavy and/or bulky objects. Low - this doesn't happen often, most of our merchandise arrive in manageable packaging. Low - from a store point of view the store is only one staff member down, workman's compensation, liability insurances come into play. Medium - unloading of truck is a part of the stocking function in our stores. Precautions such as hand trucks and proper training can be utilized to manage this risk.

*High, medium or low designation for these three columns.

RISK RESPONSE: The discussion below should focus on how the company will respond if the risks occur. This discussion could also be included as a column in the risk register.
1. Risk Response One - Inability to receive merchandise from suppliers in china. * Global risk*

locating manufactures in other regions that can supply required products can mitigate the effects of having that source of goods removed. Mexico, South America, Eastern Europe and Cuba appear to be good areas to look to find manufacturing facilities to supply cost effective products. These manufactures should be contractually obligated to uphold the same standards held by the current suppliers. It would be advisable to avoid any more suppliers in Asia until this current issue stabilizes. there are some exploitable risks that should also be addressed. First, if we start increasing our suppliers outside of china and no longer are receive Chinese goods, we may be able enhance our public image releasing that we have purposely left our Chinese manufacturers because of out disenchantment with china's current policies. Second, if conflict seems imminent, we may be able to increase our sales of emergency kits (both in store and online). Especially, If we include Potassium iodide and Zofran, in some circles these are touted as anti radiation drugs. In reality, one will prevent thyroid cancer due to radiation exposure, the other prevents nausea from radiation exposure. We can package them as an added bonus to our existing kits at no added cost. Lastly there is the possibility that we may be able to successfully win contracts with one or more branches of the military for basic products. To this end sales and marketing personal should be reaching out to various branches of the military and government to keep up to date on all contracts that are open or opening for bid.

2. Risk Response Two - HIPAA data exfiltration by attack of the company network.

Once a data breach has been discovered, the investigation and remediation phase will begin. From the information security point of view, this is incident response. In the incident response the following steps will occur; Identification, Containment, Eradication, Recovery, and Lessons Learned. More on the Incident Response plan is located in the procedural document "Incident Response Plan". Depending on the specialties required, outside venders may be brought in to supplement the security staff. After the investigation and remediation phase has completed , communication to stake holders, proper external agencies, affected customer, and the general public should begin. The findings of the investigation and remediation phase should be reviewed and recommendations acted upon. Verify that corrections been made to prevent re-infection. Also a yearly cycle of independent security audits and penetration tests should be initiated to validate the current state of the network. This should will be viewed as a preventative measure against future events and the provide a cost saving when compared to the overall cost of the breach.

3. Risk Response Three - A pharmacy gives a customer incorrect prescription medicines.

Safeguards will be put in place to prevent further occurrences of this issue. The first of those will be the purchase of prescription filling software/ automated counting devices. One that not only shows examples of the product that should be dispensed but also scans the barcodes of all items involved. Packages like HBS Pharmacy Software, PioneerRX, and Winpharm are some of the leaders in the field and should be considered for immediate adoption. This will need to be adopted in all location to provide uniformity across the corporation. New workflows will need to be implemented and followed with an emphasis on customer care not volume. The newly implemented workflow should incorporate rechecking of orders done by another person (an accuracy checking role), or at the very least delayed self-checking rather than immediate self-checking. Also in the workflow there should be clearly assigned duties to the staff. With the workflow implemented mandatory breaks can be scheduled, which should reduce stress and fatigue the may cause filling errors. Due to size constraints in the pharmacies not all of the recommendations that follow, may be able to be implemented, exceptions will be granted on a case by case basis. All pharmacies should have a large clutter free work space for the staff to work from. The pharmacies work area should be a distraction free zone, and staff working with pharmaceuticals should not be interrupted. Pharmacy staff working with pharmaceuticals should not performing multiple roles (cashier, cleaner, or answering the phone ). lastly drugs with similar names or appearance should not be stored near each other, in the near future a guidance document will be issued outlining mandatory drug separations.

4. Risk Response Four - A robbery at a Bill's Drug location.

All staff should receive regular training not to resist an attempted robbery, and what to do to minimize the chance of violence. In all trainings it should be emphasized that the safety of the staff members and customers is of primary importance. Another immediate policy change will be staffing, There will need to be an effort made at all locations to have no less than two staff members on duty at all times during working hours. During non business hours and times where there is only one staff member present, all exterior doors must remain closed and locked.

Additional security items should added to the stores as well. Closed circuit cameras mounted in conspicuous location including all cash registers and the front door. These cameras are meant to be seen, and should be visible. Even if a store has domed cameras to deter and/or observe shoplifting , these visible cameras should be implemented. Installation of panic buttons near the cash registers, in the pharmacy, and managers office should occur as soon as possible. Drop safes should be installed in all location, while there is no company standard at this time, a deposit safe that only opens during specific hours is preferred.

The cash on hand at the register should be limited. The working amount to be left in the register is to be decided by the manager based on need and business patterns. Cash drops to the safe should be made regularly to ensure that there is never a large sum in the register. Lastly, anytime the safe is open, the office door is to be shut and locked. prior to opening the office door for any reason, the safes doors must be shut and locked.

5. Risk Response Five - Economic recession.

It will need to be determined what products and product lines types are selling and provide the best profit during the economic downturn. Using the information captured from our store sales, online sales, reward card program, and market /industry research, will attempt to locate any trend. Once a trend is discovered, We will enhance the lines that are selling well in the hopes of providing a profit margin. Other ways to increase the sales of these profitable items is to move them to primary positions on the shelves and on end caps.

The prices of comparable products sold by our competitor will need to be monitor. we will initiate a program of sale page review and on site observation to insure our prices are still competitive or superior to our competition. Also we can introduce other lines that may offer an low cost alternatives to items that our competitor has that we do not currently provide.

There should also be an increased emphasis on the development of our web based and mail order pharmacy (including the pet medicine sites). This is a profitable avenue that services the nation and can provide an additional revenue stream. Increased advertising with competitive merchandise should further increase over all profits given the national or potentially global customer base. Lastly, public relation campaigns should be launched portraying our chain as "Providing value for your hard earned money, because we care". Some examples of the campaigns and initiatives follow. Introduce programs to get low cost medication to the needy. Introduce programs to get low cost medication for the pets of people that cannot otherwise afford them. Find a way to offer free or low cost medical screenings in store. any event or promotion that gets people into the stores. The company should also be examining highly visible donations to charities that affect the well being of the community. All public relation projects will need to be approved by the marketing department to ensure they are in line with current marketing strategies and will yield the desired results.

6. Risk response Six - Power outage at store with expected duration of less than one hour. To mitigate the risk at least 5 battery back-up systems and flashlights should be in place at each store, possibly more dependent on sales volume. the back-up system should provide at least 100 minutes of service time, and power condition. Placement of the systems are as follows, one unit in the pharmacy to keep that area operational. A unit will be placed at the front end registers to keep a register operational as well as all accompany point of sales equipment. another unit will be placed in the pharmacy to keep the pharmaceutical refrigerator running to prevent medicine spoilage. a fourth unit will be in the office to keep the primary computers running, and lastly there will be a unit in the equipment closet to keep the backup server and networking equipment operational.

when a power failure occurs staff should retrieve the flashlights located near the battery backup systems, one of the staff should then lock the front door and place a sign apologizing for the store being temporarily closed business hours. Customers that are in the store should be asked politely to make their purchases and leave , the units on the battery backup systems will be able to allow the customers complete their transaction, once all customers have completed their transactions all the equipment can be shut down in accordance with end of day procedures.

7. Risk response Seven - Loss of customer prescription data due to localized IT failure

To mitigate this risk the primary store drive should be mirrored to a backup server in another part of the store. Both the backup server and the primary server should be on separate battery backup units. the reason that they should be separate units is to avoid a single point of failure. Also both servers should be subject to a regular maintenance regime to avoid common equipment failures whenever possible. An added bonus to this set up is that if the primary server fails, the backup can promoted to run the store until the required repairs can be made.

Given the low cost of high speed internet, the sever should also transmit changes to the corporate servers every hour and on demand. This will create an offsite backup the data to guard against loss due to an event that might destroy the both the primary and backup drives. As an added bonus customers will able to have their prescriptions filled at any location in the chain, and moving from one location to another is as simple as access the data and moving the users data to the new server. As an interesting security note the fact that prescription data can be queried in real-time there is virtually no chance for prescription abuse (double filling).

8. Risk Response Eight - Work related back injury (store level)

All staff members will receive training on how to properly lift materials, the safe use of material handling equipment (hand trucks and pallet jacks), and personal protective equipment. Posters on the proper way to lift should be posted in the break room and in the store room. At all store locations there shall be a selection of back support belts to be issued to staff members and to be worn while performing the stocking function. Also eye protection, work gloves, hand trucks, pallet jacks and or rolling work tables should be readily available to the staff members should they desire them. If an item is not easily carried, it should moved via hand truck or rolling cart. There should be no stigma attached to the choice to use a hand truck.

At the purchasing department level, effort should be made to ensure that products we purchase come in manageable packaging. Cartons or cases that are delivered to us should be designed to be easily carried, since this can be added contractual obligation, it suggested that all new contracts be review to see if this is viable. lastly, Since we pay a premium for insurance, we should ask the insurance company to come out and review our procedures and make suggestions as to what we could do better to prevent this risk. Having the insurance company become a partner in our employees well being may lead a reduced rate over time

Similar Documents

Free Essay

Jit2 Task 1 Instructions

...SUBDOMAINS: 325.3 ­ SOLVING PROBLEMS & MAKING DECISIONS 326.3 ­ EVALUATING ECONOMICS OF MANAGEMENT DECISIONS 326.4 ­ MANAGING ENTERPRISE RISK & CONTINUITY 329.5 ­ USING INFORMATION SYSTEMS FOR COMPETITIVE ADVANTAGE   Competencies: 325.3.4: Problem Solving ­ The graduate applies the problem solving process to solve organizational and team problems, and develops strategies to avoid decision­making pitfalls. 326.3.1: Decision Analysis ­ The graduate analyzes risks and values and uses a variety of decision analysis tools and decision theory to evaluate alternatives during decision­making processes. 326.4.1: Enterprise Continuity ­ The graduate analyzes enterprise continuity plans and the continuity planning process to ensure the inclusion of essential elements, processes, and stakeholder roles. 326.4.2: Continuity and the Global Marketplace ­ The graduate applies international standards to company operations and assesses and recommends strategies for maintaining organizational stability and continuity in the global marketplace. 326.4.3: Contingency Planning ­ The graduate develops and analyzes organizational contingency plans for responding to sudden and rapid environmental changes. 326.4.4 Risk Evaluation and Mitigation ­ The graduate evaluates internal and external risks and recommends risk mitigation strategies and techniques to an organization. 326.4.5: Organizational Risk Management Programs ­ The graduate develops and assesses enterprise risk manage...

Words: 923 - Pages: 4

Free Essay

Jit2 Risk Management Task 1

...a business continuity plan Total facility lost due to a hurricane. XYZ Bakery Supply is a global company with a full range of innovative products and application expertise in the bakery, and patisserie sectors. Products and services are available in more than 100 countries around the world, and in many cases actually produced there by our subsidiaries. Clients are artisans, industry, retailers and food service. XZY Bakery Supply aim to be "reliable partners in innovation" wherever we are in the world, and so help our customers deliver nutritious, tasty food for the communities they live in Business Contingency plan as be simply defined as identification and protection of critical business processes and resources and preparing a process to ensure to survival of the organization during a times of business disruption (Hiles, A., 2007). In any well formulated Business contingency plan (BCP) there will be five integral parts which is layout in Business contingency plan of XYZ Bakery Supply for total facility lost due to a hurricane. B1: Pre-Incident Preparedness In a Pre-incident strategies, we will implement procures that help us mitigate the impact of downtime during the total loss of facility. In this Pre-incident strategy the company will mandate a Business Contingency policy following in case of imminent approach of a powerful hurricane. * CEO, COO and CFO will monitor the hurricane and will make recommendation to close the faculty for safety. * All the department...

Words: 1943 - Pages: 8

Premium Essay

Risk Management Task 1a

...Running head: JIT2 (RISK MANAGEMENT): TASK 1A 1 JIT2 (Risk Management): Task 1A It has been stated that, "Denial is a common tactic that substitutes deliberate ignorance for thoughtful planning," Charles Tremper (n.d.) who authored various risk management books. We have been hired, as a consultant in our first task is to create and present to management of business contingency plan combined with risk management to our new client. There has been some concern from both the IT department and legal departments about personal identifiable information sensitive information, client records, and other sensitive information regarding the ethical use and protection of this information. Our goal is to have client confidence along with some sense of job satisfaction; therefore, our boss has informed us that we get to choose our very first client. Our selection can be the place we actually work, any local business, or even a Fortune 500 company. One requirement is that our client must operate globally throughout its business. We will exclude any proprietary information, confidential information, or anything that can be considered sensitive. No names of real people involved with the business, any suppliers, or anything else that could be identifiable will be used. Instead we will only use made-up or fictional names for this task. No actual financial data will be used but rather be addressed using vague or generic terms when appropriate. Due to concerns in the global marketplace...

Words: 3310 - Pages: 14

Premium Essay

Strategic Managment

...srt THE COHESION CASE: ADIDAS GROUP - 2011 Evaluation of Vision/Mission Statement 1. The Adidas Group strives to be global leader in the sporting goods industry with brands built on a passion for sports and a sporting lifestyle. * Market * This mission component clarify that AG compete with other competitors such as Nike, Under Armour (UA), Callaway Golf (ELY), and the Armani Group. 2. We are committed to continuously strengthening our brands and products to improve our competitive position. * Products or services * In this component of mission statement, Adidas Group has sold three main product groupings to their customers which are footwear, apparel and hardwear. * For example, Adidas even become the major supplier of team kits for international football teams to remain international competitive. 3. We are innovation and design leaders who seek to help athletes of all skill levels achieve peak performance with every product we bring to market. * Technology * Regarding to the component in this statement, it can be seen that the new Adidas product is the Adizero Feather, the lightest everyday running shoe weighing only 160g which enables the athletes to run faster and improve performance. 4. We are consumer focused and therefore we continuously improve the quality, look, feel and image of our products and our organizational structures to match and exceed consumer expectations and to provide them with the highest value. * Customers ...

Words: 421 - Pages: 2

Premium Essay

Risk Mgmt

...Task 1 (C) – JIT2 Risk Management C. Recommendations Create an implementation plan in which you recommend ways of implementing, monitoring and adjusting the BCP. For the task of creating a Business Continuity Plan (BCP), I will follow a logical and systematic formula for implementation, monitoring and reviewing the plan for United Health Group. The goal is to minimize the impact of any disruption by containing it within a predictable and predetermined period of time. To do this, I recommend that this plan be developed and implemented with as many preventative controls, contingency resources, and procedures designed to allow the organization to quicky bounce back from any long-term business interruption. With this document I’ll present a workable DR plan that focuses not only on safeguarding critical data but also on the restoration of all normal business functions. The process for developing a sound Disaster Recovery plan will involve many layers of detail from the obvious to the not so obvious. Since disasters are by their nature unpredictable, this DR plan must be thorough enough to provide a certain amount of relief to know that if one does occur, the affects on the business will not be catastrophic. Disaster Recovery Topics: 1. Secure executive-level leadership commitment Senior leadership buy-in and support is critical to the long-term success of any enterprise level initiative. Disaster Recovery and Business Continuity Plans are no different. Further...

Words: 2044 - Pages: 9

Premium Essay

Risk Management

...JIT2 (Risk Management): Task 1A Our firm has been hired as a consultant, the first task my team and I have been assigned is to create and present to management both a risk management and a business contingency plan for our client. Both the legal and IT departments have expressed their concerns regarding the ethical use and protection of sensitive data, customer records, and other information systems content of both the firm and the client. In an effort to follow the company’s goal of each project building employee confidence and job satisfaction, the team has been allowed to select our first client. The client we choose can be a former or current employer, any local business, any nationally or internationally held publicly traded or privately held company. The one prerequisite is that the client operate globally in at least one aspect of it business. To help ensure anonymity and security any information that could be considered confidential, proprietary, or personal in nature will be excluded. No actual names of people, suppliers, the company, or other identifiable information will be included. In addition every effort will be made to ensure fictional names used will be obscure as possible. Company-specific data, including financial information, will be addressed in the most general and generic means possible when appropriate. Per the client’s request will address the following items: A. Generate a risk register that includes eight valid risks faced by the client. The...

Words: 2097 - Pages: 9

Premium Essay

Jit2 Task

...JIT2 Task (A) Risk Management Register: Risk | Description | Owner | Source | Likelihood of Occurrence* | Severity of Impact* | Controllability* | Macroeconomics Risks | Economic downturn could pose risk to sales development. | Accounting Team/Sales Team | Poor economy, not enough jobs, people not purchasing as much | High | High | Low | Consumer Demand Risks | Not being able to respond to consumer wants/demands quickly enough, leading to short-term revenue loss | Marketing Team | Consumer interests change, other companies offer newer/better product | Medium | Medium | Medium | Industry Consolidation Risks (bargaining power) | Decreased bargaining power, price wars, inflated discounts, limited space within retailers | Sourcing, Pricing, Marketing and General Counsel Legal Teams | Market consolidation and strategic alliances | High | Medium | Medium | Political and Regulatory Risks | Trade policies | Government Relations Team/General Counsel Legal Team | Restrictions on importing and tariffs that disrupt free flow of goods | Medium | Medium | Low | Legal Risks | Patents and third-party trademark infringement- must be careful not to raise concern for risk when creating and marketing new products | General Counsel Legal Team | Many competitors in same business marketing similar products | Low | Medium | High | Product Counterfeiting and Imitation Risks | Other vendors stealing logos and designs and portraying their imitation products as original | Product Branding...

Words: 1606 - Pages: 7

Premium Essay

Risk

...JIT2 Task 1 Part B ManIT, LLC Business Continuity Plan The information below is a Business Continuity Plan for ManIT, LLC to follow in the possible aftermath of a disaster causing major disruptions to the business. Preparation, response, and recovery from a disaster affecting the operations of ManIT, LLC, requires the full efforts of multiple personnel in many different departments. If such of an event does happen, this plan could be followed and monitored by the Continuity Management Team within ManIT, LLC. The Business Continuity Plan gives the responsibilities of the Continuity Management Team, where their goal is to make procedures that will help with the ManIT, LLC business functions. If such an event or disaster that does affect any functional area of the business, the Continuity Management Team would be there to facilitate all of the areas affected by the event or disaster and personnel involved. This team should include other smaller groups that would entail operations and communication, and damage assessment with each role of the groups to be defined whenever a major business disruption occurs. The leader of the Continuity Management Team will be a Coordinator and would be the central point of contact for all execution of plans. B1. Strategic Changes There are many changes that ManIT, LLC should implement to ensure that operations should continue should a disruption occur. In recent year, the Department of Homeland Security recommended...

Words: 2086 - Pages: 9